exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 86 discussion

Actual exam question from CompTIA's PT0-002
Question #: 86
Topic #: 1
[All PT0-002 Questions]

A security professional wants to test an IoT device by sending an invalid packet to a proprietary service listening on TCP port 3011. Which of the following would allow the security professional to easily and programmatically manipulate the TCP header length and checksum using arbitrary numbers and to observe how the proprietary service responds?

  • A. Nmap
  • B. tcpdump
  • C. Scapy
  • D. hping3
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dsm
Highly Voted 2 years ago
Selected Answer: C
Scapy is manipulation tool
upvoted 10 times
...
RRabbit_111
Highly Voted 1 year, 9 months ago
The correct answer is D. hping3. hping3 is a packet crafting tool that allows a user to easily craft and manipulate custom TCP packets, including the ability to adjust the TCP header length and checksum. It also allows the user to observe how the target responds to the custom packets. By contrast, Nmap is a port scanning utility, tcpdump is a packet sniffer, and Scapy is a powerful packet manipulation tool, but none of these tools have the same capabilities as hping3.
upvoted 6 times
beamage
1 year, 8 months ago
HPing3 observe the response
upvoted 1 times
...
...
Marty35
Most Recent 5 months, 1 week ago
Scapy can't observe how a service responds, but hping3 can.
upvoted 2 times
...
solutionz
1 year, 3 months ago
Selected Answer: C
The tool that allows a security professional to programmatically manipulate TCP header length, checksum, and other packet details using arbitrary numbers is: C. Scapy Scapy is a powerful Python library and interactive tool that enables the creation, manipulation, sending, and receiving of network packets. It is often used for network discovery, scanning, and vulnerability testing, and it can be very useful when testing how a proprietary service responds to specifically crafted or invalid packets. Options A, B, and D are valuable tools in the networking and security domains, but Scapy is particularly well-suited for this kind of packet manipulation and analysis.
upvoted 1 times
...
Gargamella
1 year, 6 months ago
Scapyy is the right. Comptia Self Study book, on appendix under crafting tool say Scapy
upvoted 2 times
...
lifehacker0777
1 year, 7 months ago
Selected Answer: C
hping3 is scriptable using the Tcl language. but, Scapy is a powerful interactive packet manipulation tool, packet generator, network scanner, network discovery, packet sniffer, etc. It can for the moment replace hping, 85% of nmap, arpspoof, arp-sk, arping, tcpdump, tethereal, p0f, …. In scapy you define a set of packets, then it sends them, receives answers, matches requests with answers and returns a list of packet couples (request, answer) and a list of unmatched packets. This has the big advantage over tools like nmap or hping that an answer is not reduced to (open/closed/filtered), but is the whole packet.
upvoted 2 times
...
nickwen007
1 year, 8 months ago
Selected Answer: C
Scapy is a powerful packet manipulation tool that allows users to craft, send, and receive custom TCP packets. It can be used to manipulate the TCP headers and to observe the response from the proprietary service.
upvoted 3 times
[Removed]
1 year, 7 months ago
Yes C is the answer
upvoted 2 times
...
...
[Removed]
1 year, 8 months ago
Share your answer Hping 3 or Scapy? my answer is Scapy
upvoted 1 times
...
Frog_Man
1 year, 8 months ago
By definition from Wiki, it is Scapy.
upvoted 3 times
[Removed]
1 year, 8 months ago
Scapy is correct because programmatically its pythone base manipulation
upvoted 2 times
...
...
kloug
1 year, 8 months ago
c correct
upvoted 3 times
[Removed]
1 year, 8 months ago
yes C is the best answer
upvoted 2 times
...
...
[Removed]
1 year, 8 months ago
C scapy correct https://scapy.readthedocs.io/en/latest/introduction.html#about-scapy
upvoted 2 times
...
2Fish
1 year, 9 months ago
I am thinking D (hiping3) as it allows you to view the response. For example, SCAPY, in this video. They had to run Wireshark on the destination machine to confirm the ICMP packet was received. https://www.youtube.com/watch?v=sXUByO9knmI
upvoted 1 times
[Removed]
1 year, 9 months ago
easily and programmatically manipulate i think C Scapy is python base
upvoted 2 times
...
...
[Removed]
1 year, 11 months ago
Scaly is a powerful interactive packet manipulation program. It replaces tools such as hping, 85% of nmap, arpspoof, arp-sk, arping, tcpdump, Tshark, p0f and others. It’s definitely C
upvoted 5 times
...
masso435
1 year, 11 months ago
Which this is why it could be both scapy or hping3 based off of what it's asking. I misspoke on the analysis of receiving packets.
upvoted 1 times
...
masso435
1 year, 11 months ago
Selected Answer: D
Scapy can only manipulate. It can't see the response back. Answer is D. https://www.kali.org/tools/hping3/
upvoted 2 times
[Removed]
1 year, 8 months ago
Scapy is also response back read again https://www.google.com/url?sa=t&source=web&rct=j&url=https://stackoverflow.com/questions/24415464/scapy-sending-receiving-and-responding&ved=2ahUKEwjb9oOkhbf9AhVL8LsIHZgLBrIQFnoECAoQAQ&usg=AOvVaw1DWU4Y56SG-aYnl7l1OVPm
upvoted 2 times
[Removed]
1 year, 8 months ago
Answer is C
upvoted 2 times
RHER
1 year, 7 months ago
podrias dejar de confundir a la gente en todas las preguntas hay una respuesta suya y a cada rato la cambias
upvoted 1 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago